Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CRISC Exam Questions and Answers

Rating
-
Sold
-
Pages
11
Grade
A+
Uploaded on
18-11-2022
Written in
2022/2023

CRISC Exam Questions and Answers

Institution
Course

Content preview

CRISC Exam Questions and Answers
How many steps in NIST RMF? - ✅ 6

Name steps of the NIST RMF - ✅ 1) Categorize Info Systems
2) Select Security Controls
3) Implement Security Controls
4) Assess Security Controls
5) Authorize Info Systems
6) Monitor Security Controls

What are the layers of COBIT? - ✅ Governance and Management

What are the Management layers of COBIT? - ✅ 1) Align, Plan, and Organize
2) Build, Acquire, and Implement
3) Deliver, Service, and Support
4) Monitor, Evaluate, and Assess

What are the layers of ISACA Risk IT Framework? - ✅ 1) Risk Governance
2) Risk Evaluation
3) Risk Response

What are the levels of SDLC? - ✅ 1) Initiation
2) Requirements
3) Design
4) Development/Acquisition
5) Implementation
6) Operations/Maintenance
7) Disposal/Retirement

What does SDLC stand for? - ✅ Software Development Life Cycle

What is the NIST Business Continuity Document? - ✅ 800-34 "Contingency Planning
Guide for Federal Information Systems"

What components of risk do Risk Scenarios include? - ✅ 1) Asset
2)Threat
3) Threat Agent
4) Vulnerability
5) Time/Location

They leave off likelihood and impact

What elements should a Risk Register include? - ✅ 1) Risk factors
2) Threat agents, threats, and vulnerabilities

, 3) Risk scenarios
4) Criticality, severity, or priority of risk
5) Asset information
6) Impact of the risk on an asset
7) Likelihood of the threat exploiting the vulnerability
8) Current status of risk response actions
9) Resources that may be committed to respond to risk
10) Risk ownership information
11) Planned milestones toward risk response

Which publication contains the NIST RMF? - ✅ 800-37

What are the distinctive processes of the NIST RMF? - ✅ 1) Prepare for assessment
2) Conduct assessment
3) Communicate results
4) Maintain assessment

Who developed the OCTAVE Methodology? - ✅ Carnegie Mellon University

What is special about OCTAVE? - ✅ Designed for big businesses

What sets OCTAVE Allegro apart? - ✅ Includes more business-centered and operation
risk approaches

What sets OCTAVE-S apart? - ✅ Designed for smaller organizations

What is ISO/IEC 27005:2011? - ✅ It is a basic risk management standard that is totally
geared towards Information Security

What is ISO 31000:2009? - ✅ Risk Management - Principles and Guidelines

What is IEC 31010:2009 - ✅ The meat of the risk management part of ISO 31000:2009

What are the three areas of the Risk Evaluation portion of the ISACA Risk IT
Framework, and what is a key component of the last one? - ✅ RE1: Collect Data
RE2: Analyze Risk
RE3: Maintain Risk Profile

Should develop KRI's in RE3

What are a few methods of data collection? - ✅ 1) Conducting Interviews
2) Documentation Reviews
3) System Observation and Verification
4) System Testing

SLE - ✅ Single Loss Expectancy

Written for

Course

Document information

Uploaded on
November 18, 2022
Number of pages
11
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$18.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller
Seller avatar
miriam4880

Get to know the seller

Seller avatar
miriam4880 panama tutors
Follow You need to be logged in order to follow users or courses
Sold
-
Member since
3 year
Number of followers
0
Documents
68
Last sold
-

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions